Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gv24-vhxm-xr5j

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web browser if a specially crafted link is visited. The JavaScript code is executed on the user's system, not executed on LXCA itself.

An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web browser if a specially crafted link is visited. The JavaScript code is executed on the user's system, not executed on LXCA itself.

EPSS

Процентиль: 54%
0.00312
Низкий

Связанные уязвимости

CVSS3: 5.4
nvd
почти 6 лет назад

An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web browser if a specially crafted link is visited. The JavaScript code is executed on the user's system, not executed on LXCA itself.

EPSS

Процентиль: 54%
0.00312
Низкий